Get in Touch
 Duration 21 hours

Course Outline

Cluster Setup

  • Implement Network security policies to limit cluster-level access
  • Leverage the CIS benchmark to assess the security configuration of Kubernetes components (etcd, kubelet, kubedns, kubeapi)
  • Configure Ingress objects with appropriate security controls
  • Secure node metadata and endpoints
  • Limit the usage of and access to GUI elements
  • Validate platform binaries prior to deployment

Cluster Hardening

  • Restrict access to the Kubernetes API
  • Apply Role Based Access Controls to reduce exposure
  • Handle service accounts with care, such as disabling defaults and minimizing permissions on newly created ones
  • Keep Kubernetes up to date with frequent updates

System Hardening

  • Reduce the host OS footprint to shrink the attack surface
  • Minimize IAM roles
  • Limit external access to the network
  • Utilize kernel hardening tools like AppArmor and seccomp appropriately

Minimize Microservice Vulnerabilities

  • Establish proper OS-level security domains using tools like PSP, OPA, and security contexts
  • Manage kubernetes secrets effectively
  • Employ container runtime sandboxes in multi-tenant environments (e.g., gvisor, kata containers)
  • Enforce pod-to-pod encryption via mTLS

Supply Chain Security

  • Reduce the base image footprint
  • Safeguard the supply chain by whitelisting image registries and signing/validating images
  • Perform static analysis on user workloads (e.g., kubernetes resources, docker files)
  • Scan images for existing vulnerabilities

Monitoring, Logging and Runtime Security

  • Conduct behavioral analytics of syscall processes and file activities at both host and container levels to identify malicious actions
  • Identify threats across physical infrastructure, applications, networks, data, users, and workloads
  • Track all phases of an attack, regardless of origin or propagation method
  • Execute deep analytical investigations to identify malicious actors within the environment
  • Guarantee container immutability during runtime
  • Monitor access using Audit Logs

Requirements

  • CKA (Certified Kubernetes Administrator) certification

Audience

  • Kubernetes practitioners

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories